Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ryu7Zz

#51667of 56,337
5Total CVSS
Vulnerabilities · 1
PT-2026-55945
5.0
2026-06-19
Langchain · Langsmith Client Sdks · CVE-2026-59152
**Name of the Vulnerable Software and Affected Versions** LangSmith Client SDKs versions prior to 0.8.18 **Description** An issue exists in the `TracingMiddleware` where an attacker can send an HTTP request to a server to force the reading of an arbitrary file from the local filesystem. The contents of the file are then uploaded to LangSmith as a trace attachment. Depending on the deployment of the distributed trace system, triggering this read may not require authentication. However, retrieving the uploaded content requires read access to the LangSmith workspace. This allows a user with low-privilege workspace access to read files from any server running the middleware, crossing the intended trust boundary. **Recommendations** Update LangSmith Client SDKs to version 0.8.18.